DOCUMENT RESUME 

ED 324 Oil IR 053 286 



AUTHOR 
TITLE 

INSTITUTION 
PUB DATE 
NOTE 



AVAILABLE FROM 



PUB TYPi 



Berman, Jerry; Goldman , Janlon 

A Federal Right of information Privacy: The Need for 
Reform. Number 4. 

Benton Foundation , Washington, oC. 
89 

43p.; Project on Communications & Information Policy 
Options, For related reports, see IR 053 287-288 and 
IR 053 300. 

Policy Option Project, Benton Foundation, 1776 K 
Street, NW, Washington, DC 20006 ($6.50 per single 
copy, $33.00 for boxed set of eight papers). 
Legal/Legislative/Regulatory Materials (090) — 
Viewpoints (120) 



EDRS PRICE MF01/PC02 Plus Postage. 

DESCRIPTORS Access to Information; Confidential Records; 

Constitutional Law; *Disclosure; Federal Legislation; 

information Dissemination; information Needs; 

Information Utilization; *Policy Formation; Political 

Issues; *Privacy; *Public Policy 
IDENTIFIERS information Policy 



ABSTRACT 

Because a right of information privacy is not firmly 
imbedded in constitutional case law, advocates of the concept that 
citizens have the right to control personal information held by 
others turned to Congress. Enacted to regulate the government's use 
of personal information, the Privacy Act of 1974 has failed to work 
in the way intended. Shortly after its passage, the political swing 
away from privacy and toward bureaucratic efficiency revealed the 
Act's structural and conceptual weaknesses. It is suggested that this 
act needs to be redrafted to strengthen its major principle— i.e. , 
that information collected for one purpose „iay not be used for 
another purpose without the individual's consent. It is also 
recommended that information legislation restrict access to personal 
information held by private institutions. Further, it is felt that 
public policy is needed in response to advanced information 
technology that imbnes institutions with the power to instantly 
exchange, compare, verify, profile, and link information in separate 
databases. This report provides guiding principles for drafting 
legislation, and concludes that statutory standards should 
incorporate a balance between the sensitivity of the information at 
stake and the institutional justification or need for the 
information. (SD) 



********* ********** ************************ ************************** 

* Reproductions supplied by EDRS are the l^>t that can be made 

* from the original document. 



U $ OCPAWTMCWT Of EDUCATION 

£C CA NA. P(SCu»C£S Sf ~«M* T CN 



o 



4 




A Federal Right of 
Information Privacy: 
The Need for Reform 

Jeny Berman & Janlori Goldman 



Benton Foundation 

Project on Communications & 

Information Policy Options 



PERMISSION TO RbPRODUCE THIS 



IT) 

!/} MATERIAL HAS BEEN GRANTED BY 

O Kar en Menichelli 

V 2 

^SJj^ TO THE EDUCATIONAL RESOURCES 

INFORMATION CENTER (ERIC) 



The Benton Foundation 

The Benton Foundation, based in Washington, D.C., is 
a private grantmakmg foundation committed to improving the 
democratic process through increased public understanding 
and use of communications and information technologies. A 
lecacv of Senator William Benton, the foundation supports 
projects in the fields of communications policy, public affairs 
and the media, and communications education. 



Benton Foundation 

Project on Communications & 

Information Policy Options 

In early 1%8, the Bentor Foundation commissioned a 
series of eight papers to explore future options for public policy 
in the communications and information arenas. Written by 
reco-nized authorities in their respective fields, the papers 
identity critical issues and options confronting policymakers 
at the federal level 

Through the publication of this series, the foundation seeks to 
stimulate public awareness and discussion of the communica- 
tions and information issues that will affect our society in the 
coming decade Two broad themes are addressed in the 
•vipers the role o policy in :V rapidly changing mass media 
marketplace, and the ethical, constitutional, and regulatory 
challenges that arise from the increasing use of computers in 
our socn*v 

The nro* »« this paper are those at the authors), and do not 
mxe^anly represent those of the Benton Foundation, its 
director*, or it-> staff 



< 198^ Benton Foundation, Washington, DC 



A Federal Right of 
Information Privacy: 
The Need for Reform 

Jerry Bermart & Janlori Goldman 



4 



About the Authors 



Jerry Berman is the Director of the ACLU Project on Privacy and 
Technology and ACLU Chief Legislative Counsel. He is Co-Chair of 
the Privacy Committee of the American Bar Association's Section on 
Individual Rights and Responsibilities. Mr. Berman has worked to 
enact major privacy legislation including the Electronic Communi- 
cations Privacy Act of 1986 and the Foreign Intelligence Surveillance 
Act of 1978. * 

Janlori Goldman is the Staff Attorney of the ACLU Project on 
Privacy and Technology. Ms. Goldman, formerly Legal Counsel of 
the Minnesota Civil Liberties Union, has participated in thedevelop- 
ment of information privacy policy. Her work has contributed to the 
passage of the Computer Matching and Privacy Protection Act of 
1988 and the Video Privacy Protection Act of 1988. 

The authors gratefully acknowledge Morton H. Halperin, Jane 
E. Larson, William L. Miller, and Albert Y. Muratsuchi for their in- 
valuable assistance and support in the editing of this paper. 



0 



5 



Executive Summary 



This paper examines the right of citizens t~ control personal 
information held by others. The right of information privacy is an 
enduring and cherished value in thiscountry, resonating at the heart 
of individual freedom, autonomy, and individuality. Crucial to 
one's sense of "self ' is the right to maintain some decision-making 
power over what information to divulge, to whom, and for what 
purpose. Yet, individuals are increasingly losing control over per- 
sonal information collected, maintained, used, and disseminated by 
both the federal government and private institutions, 

Because a right of information privacy is not firmly embedded 
in constitutional case law, privacy advocates have turned to Con- 
gress. The Privacy Act of 1974, which was enacted to regulate the 
government's use of personal information, has failed to work in the 
way intended by Congress, Shortly after its passage, the political 
swing away from privacy and towards bureaucratic efficiency re- 
vealed the Act's structural and conceptual weaknesses. The Act 
needs to be rewritten to strengthen its major principle — informa- 
tion collected for one purpose may not be used for a different 
purpose without the individual's consent. 

In addition, information privacy legislation is needed to restrict 
access to personal information held by private institutions. Con- 
gress has enacted laws to protect records held by banks, schools, the 
credit industry, cable and video companies, and others, These laws 
serve as precedents for legislation that establishes on a case-by-case 
basis an incremental series of privacy rights in information held by 
the government and private institutions, including protections for 
medical, insurance, personnel, and retail records. Further, public 
policy is needed in response to ad' unced information technology 
that gives institutions the power to instantly exchange, compare, 



ERLC 



i 

e 



I. INTRODUCTION 



The constitutional right to privacy is, as Justice Brandeis first 
stated, "the right to be left alone— the most comprehensive of rights 
and the right most valued by civilized men." 1 Brandeis' formulation 
has long been the starting point for any discussion of the meanir.g of 
privacy. But what value does privacy hold for us? What does privacy 
look like in the late 1980s? Are we truly able, or even entitled, to live 
certain areas of our lives outside of the public eye? Is privacy still the 
most valued and comprehensive of rights? 

"Who cares about privacy?" 2 National polls document a grow- 
ing public demand for privacy protection. In a 1983 analysis of their 
survey results, Louis Harris and Associates concluded: 

Particularly striking is the pervasiveness of support for 
tough new ground rules governing computers and other 
information technology. Americans are not willing to en- 
dure abuse or misuse of information, and they overwhelm- 
ingly support action to do something about it. This su^ t d 
permeates all subgroups in society and represents a man- 
date for initiatives in public policy. 3 

Most people cherish their right to be abk ^o live certain areas of 
their lives outside of the public eye. 4 Yet today, these same people 
are overwhelmed by institutional demands for information. Crucial 
to one's sense of "self" is the right to maintain some decision-making 
power over what information to divulge, to whom, and for what 
purpose. Although there is broad public support for privacy, indi- 
vidual voices are often scattered and powerless, forcing a reliance on 
organized constituencies. 

The confirmation hearings of Judge Robert Bork to the United 
States Supreme Court brought home the degree to which an 
individual's sense of freedom and identity depends on governmen- 
tal respect for privacy. Voicing this belief, the majority of Senators 
who voted against Judge Bork's confirmation expressed concern 
over Bork's hostile view of the constitutional right to privacy. 

1 



Citizens are losing control of personal, sensitive information as 
government agencies and private institutions escalate the collection 
and exchange of personal information. In 1988, a number of federal 
agencies proposed massive expansions of their information systems 
by linking their records with the separately maintained record 
systems of other agencies. The FBI, for example, proposed enhanc- 
ing its law enforcement efforts by connecting its National Crime 
Information Center (NCIC) to the computerized record systems of 
the Department of Health and Human Services (HHS), the Internal 
Revenue Service (IRS), the Social Security Administration (SSA), 
and the Immigration and Naturalization Service (INS). The Bureau's 
plan was ultimately defeated, in part due to the efforts of privacy 
advocatesand computer security experts who submitted a report to 
the agency recommending that the linkage proposal be abandoned. 5 
However, other proposals may soon be implemented. HHS recently 
announced its plan to link electronically thousands of computers 
containing the prescription records of Medicare beneficiaries in 
pharmacies i Hionwide. HHS claims this new system will stream- 
line the Medicare bureaucracy. 6 

Many have long feared that such coordinated information 
collection would eventually lead to the creation of a national data- 
basecontaining lifetime dossiers on all citizens, held in one centrally 
controlled mainframe computer. However, advanced information 
technology now allows information maintained in completely s ka- 
rate databases to be linked. In a recent study, the Office of Technol- 
ogy Assessment (OTA) concluded that a dt facto national database 
already exists on U.S. citizens. 7 Privacy legislation is necessary to 
respond tothe present rial ity that advanced information technology 
now gives institutions, both public and private, the power to nearly 
instantly exchange, compare, verify, profile, and most importantly, 
link information. 

Technology has overtaken current law, leaving society without 
a new set of social mores to limit and define the extent to which 
advanced technology can be used to know all we can about each 
other The danger is that a watched society is a conformist society, 
one in which people are afraid to act or believe in ways that call 



ERIC 



2 

9 



the Constitution to grant individuals a right of privacy, based on the 
First Amendment freedom of association and expression, 10 the Fifth 
Amendment privilege against self-incrimination, 11 penumbras of 
thp Bill of Rights and the Ninth Amendment, 12 the Fourteenth 
Amendment's guarantee of "ordered liberty", 13 but principally rooted 
in the Fourth Amendment protection of persons, places, papers, and 
effects against unreasonable searches and seizures. 14 . The primary 
concern of this section is whether there is a constitutional right to 
privacy in personal information held by others and whether restric- 
tions may be placed on personal information held by the govern- 
ment. 

The Fourth Amendment was drafted two hundred years ago to 
curtail the "writs of assistance" used by officials to search door-to- 
door for British tariff law violations. The Framers could not imagine 
today's widespread collection and use of personal information by 
businesses and other institutions or the massive and easily accessed 
body of personal information held by the government. In the 1700s, 
"personal information was difficult to collect, and files were hand- 
written, rarely reproduced and easily lost." 15 However, despite 
major changes in the way individuals handle their papers, the Court 
has been reluctant to extend the reach of the Fourth Amendment to 
protect records from intrusion once they are held by someone else. 

The application of the Fourth Amendment had traditionally 
hinged on property-based notions of liberty that ground peop^s' 
rights in their relationships to particular places, such as the "home- 
as-castle." However, in an early case, Boyd v. United States, the 
c upreme Court brought the Fourth Amendment into the late nine- 
teenth century, reasoning that the founding principles of the Amend- 
ment were broadly worded to. 

apply to all invasions on the part of the government and its 
employees of the sanctity of a man's home and >he privacies 
of his ^ fe. It is not '.he breaking of his doors or the rummag- 
ing of his drawers that constitute the essence of the offense, 
but it is the invasion of his indefensible right of personal 
security, personal liberty and private property. 16 



ERIC 



U 4 



The Fourth Amendment the Boyd Court noted, reflects the colonists' 
struggle with the arbitrary power of government. Thus, they cau- 
tioned, "constitutional provisions for the security of property and 
person should be liberally construed. A close and literal construc- 
tion deprives them of half of their efficacy, and leads to a gradual 
depreciation of the right, as if it consisted more in soun^ than in 
substance." 17 The Justices recognized that the Fourth Amendment 
protection of property extends to government intrusions outside 
one's home. 

The Constitution also has been interpreted to extend protection 
to information that implicates both First Amendment and nrivacy 
values. In NAACP v. Alabama," the Court recognized the severe 
chilling effect on First Amendment freedoms that can resu It from the 
unauthorized disclosure of an organization's membership, finding 
damage in the mere revelation of one's personal political beliefs. 

In 1967, the Supreme Court, in ruling that warrantless wiretap- 
ping is unconstitutional held that the Fourth Amendment protects 
people, not places. (Katz v. United States* 9 ) In Katz, the Court set 
forth a standard for determining constitutionally protected "zones 
of privacy" — whether the expectation of privacy in the area to be 
searched outweighs the government's interest in searching that 
area, factoring into this analysis the degree of intrusion involved. 
WiU Katz and preceding cases, the Court developed an interpreta- 
tion of the Fourth Amendment, and the Bill of Rights as a whole, as 
protections not only of tangible property, but also of an individual's 
communications, personality, politics, and thoughts. 

The problem with the Katz formulation is that its relative 
standard — a "reasonable expectation of privacy" — can only 
reflect, not prevent, deterioration in societal respect for privacy. 
Applying this "reasonable expectation" standard, the Court in later 
cases often determined that an individual's privacy had not been 
violated by certain intrusions because society's "expectation of 
privacy" had been persistently lowered by the circumstances of 
modern existence. Many people can no longer claim to reasonably 
expect privacy even in the most intimate activities of their lives. 20 



ERLC 



5 

12 



privacy he asserted was not reasonable. 24 The Court reached this 
conclusion even though most bank customers probably do have an 
expectation of privacy in these records. 

The Court in Miller applied a flawed principle. Banks maintain 
customer records both as a service to customers and for the barks' 
own recordkeeping purposes. The customer may voluntarily relin- 
quish physical possession of his or her records (or maintain dupli- 
cates) buf clearly does not intend to lose all control over those 
records. 2 " Customer continue to maintain an interest in the records 
of a transaction bee. e those records directly represent the transac- 
tion. As Justice Brendan dissented in the 5-4 opinion ir the Miller 
case: 

A bank customer's reasonable expectation is that, absent a 
compulsion by legal process, the matters he reveals to the 
bank will be utilized by the bank only for internal banking 
purposes. ... [A] depositor reveals many aspects of his 
personal affairs, opinions, habits, associations. Indeed, the 
totality of bank records provides a virtual current biogra- 
phy. . '.Development of photocopying machines, electronic 
computers and other sophisticated instruments have accel- 
erated the ability of government to intrude into~ *eas which 
a person normally chooses to exclude from prying eyes and 
inquisitive minds. Consequently, judicial interpretations of 
the constitutional protection of individual privacy must 
keep pace with the perils created by these new devices. 26 

People do expect that they are enlitled to privacy in their 
financial affairs. Such a right is essential in a modern society. 
Financial records, and other records that reflect what we buy, where 
we travel what we read, who we communicate with, are extensions 
of our selves, regardless of where they are stored. They are Ihe 
papers" explicitly and separately named as protected by the Fourth 
Amendment. Nowhere in the Amendment does it say that one's 
papers must be kept in the home in order to be safe from unwar- 
ranted government intrusion. 



7 



maintenance of personal information in centralized, computerized 
files rise* to the level of constitutional invasion into an individual's 
privacy. In Whalen v. Roe, 2 " the Court held that a state may maintain 
files containing the names and addresses of all people who lawfully 
obtain prescription drugs. The Court found that although one may 
assert a constitutional privacy right to not disclose personal matters, 
the itate'scentralized file did not pose a "sufficiently grievous threat 
to disclosure." In one sense, Wlialen may be viewed as a positive 
decision because the Court upheld the statute in question on the 
grounds that it incorporated "due process safeguards," such as 
confidentiality and security provisions, to protect against unwar- 
ranted disclosures. 

The Whalen Court asked whether the government's collection of 
personal information posed a threat to privacy, and decided that it 
did: 

We are not unaware of the threat to privacy implicit in the 
accumulation of vast amounts of personal information in 
computerized data banks or other massive government 
files. The collection of taxes, the distribution of welfare and 
social security benefits, the supervision of public health, the 
direction of our Armed Forces, and the enforcement of the 
criminal laws, all require the orderly preservation of great 
quantities of information, much of which is personal in 
character and potentially embarrassing or harmful if dis- 
closed. The right to collect and use such data for public pur- 
poses is typically accompanied by a concomitant statutory 
or regulatory duty to avoid unwarranted disclosures. [We] 
recognize that in some instances that duty arguably has its 

roots in the Constitution Broad dissemination of such 

information, however, would clearly implicate constitu- 
tionally protected rights. . . .[T]he central computer storage 
of the data thus collected. . . vastly increases the potential for 
abuse of that information. 28 



ERIC 



9 

1 6 



The Fourth Amendment is elastic enough to apply to privacy 
intrusions created by advances in information technology and pol- 
icy. Because the Court has rigidly refused to expand the scope of the 
Fourth Amendment to explicitly recognize the right to be secure in 
one's persor- 1 papers held by others, privacy advocates have turned 
to Congress to address the issue in legislation. Congress has re- 
sponded by creatirg zones of privacy around certain information, 
and enacting a number of information privacy statutes in direct 
response to Supreme Court decisions. 29 

III. THE CONGRESSIONAL RESPONSE 
A. The Privacy Act of 1974 

Congress has struggled with the problems posed by increasing 
information collection and use, and the development of new infor- 
m?tion technologies that transform the way institutions handle 
information. In the 1960s and early 1970s, Congress held a series of 
hearings on computers, privacy, and the protection of personal 
information ™ Throughout most of the 1960s, Congress considered 
a proposal to create a centralized national data center on all U.S. 
citizens containing information such as Social Security numbers, 
andincomeand censusdata. Backers of the proposal argued that the 
center was necessary to serve the needs of the " welfare state." After 
years of hearings studies, and debates, the national data center was 
overwhelmingly condemned as "Big Brother" government, and a 
threat to individual autonomy, dignity, and liberty. 

At a 1%6 hearing, one Representative expressed fear that a 
centralized federal facility, into which would be "poured informa- 
tion collected from various government agencies and from which 
computers could draw selected facts, . . . could lead to the creation 
of the 'Computerized Man'. . . stripped of his individuality and 
privacy " v At the same hearing, Representative Frank Horton (R- 
NY) extolled the virtuesof ineff iency and bureaucracy: "One of the 
most practical of our present safeguards of privacy is the fragmented 



ERIC 



nature of present information. It is scattered in little bits and pieces 
acrcss the geography and years of our life. Retrieval is impractical 
and often impossible. A central data bank removes completely this 
safeguard." 32 The plan was abandoned. 33 

It should be noted that one witness at the 1966 hearing on 'The 
Computer and the Invasion of Privacy" warned privacy advocates 
of the dangers of focusing attention on the central data bank issue: 

The problems of tha invasion of privacy are, in my view, 
significant, and they will exist whether or not the central 
computer bank is created by the Government. Individual 
data systems, both public and private, now being devel- 
oped, can be tied together eventually into a network that 
will present essentially the sair e problems .... Today we are 
already building the bits and pieces of separate automated 
information systems *n both the private and government 
sectors that so closely follow the pattern of development to 
the present integrated communications structure that a de 
tacto version of the system you are now pondering is 
already in the construction phase. It is in many ways more 
dangerous than the single data bank now being consid- 
ered. 34 

By 1973, the Watergate scandal contributed to what had become 
a national crisis of faith in government institutions and a heightened 
sensitivity to the unfettered ability of the government to ntrude into 
the personal affcirs of its citizens. In this environment, the pub'ic 
became increasingly concerned about the unhampered collection 
and use of personal records by the government: 

Accelerated data sharing of such personally identifiable in- 
formation among increasing numbers of federal agencies 
through sophisticated automated systems, coupled with 
the recent disclosures of serious abuses of governmental 
authority represented by the collection of personal dossi- 
ers, illegal wiretapping, surveillance of innocent citizens, 
misuse of tax data, and similar types of abuses, have helped 



9 

ERIC 



n 

18 



4) The right to privacy is a personal and fundamental right 
protected by the Constitution of the United States; and 



5) In order to protect the privacy of individuals identified 
information systems maintained by Federal agencies, it is 
necessary and proper for the Congress to regulate the 
collection, maintenance, use, and dissemination of informa- 
tion by such agencies. 37 

In introducing the Senate veision of the Bill, Senator Sam Ervin 
(D-NC) said: "[T]he appetite of government and private organiza- 
tions for information about individuals threatens to usurp the right 
to privacy which I he. ong felt to be among the most basic of our 
civil liberties as a free people. . . . [T]here must be limits upon what 
the government can know about each of its citizens/' 38 In drafting 
the Privacy Act, Congress sought to block the creation of a national 
data center containing personal information, and curtail the use of 
the Social Security number (SSN) as a uniform national identifier. 
Further, Congress favr.d that ' [i]f the use of the SSN as an identifier 
continues to expand, the incentives to link records and broaden 
access to them are likely to increase." 39 

The purpose of the Act was to "promote accountability, respon- 
sibility, legislative oversight and open government with respect to 
the use of computer technology in the personal information systems 
and databanks of the federal government." 40 The Act was to serve 
as an "Information Bill of Rights" for citizens and a "Code of Fair 
Information Practices" for federal agencies. 

To accomplish these goals, the Act establishes a right of privacy 
in personal information held by federal agencies. With certain 
exceptions, the Act prohibits government agencies from disclosing 
information collected for one purpose for a different purpose with- 
out the individual's consent. Under the Act, citizens have a right of 
access to their records and the opportunity to amend their records 
upon showing that they are not accurate, relevant, timely, or com- 
plete. The Act also limits the use of the Social Security number for 
identification purposes, unless otherwise authorized by law, and 



ERIC 



13 

20 



prohibits the government from collecting information on the politi- 
cal activities of citizens. Individuals may sue for injunctive relief to 
enforce some of the Act's provisions, and damages may be awarded 
by proving that harm occurred as the result of a willful or intentional 
agency violation of privacy. 

The Privacy Act reflects a compromise between very different 
House and Senate passed bills. The Senate bill created a Privacy 
Board with oversight powers. The House bill, supported by the Ford 
Administration, emphasized access to and correction of records. In 
the final negotiations, many of the stronger Senate provisions were 
dropped. 

Despite the good intentions and clear objectives of its drafters, 
the Privacy Act has fallen far short of achieving many of its original 
goals, at best serving as a procedural hoop-jump for federal agen- 
cies. A number of factors have severely undermined the Act's 
effectiveness, including flaws in the Act itself, administrative inter- 
pretation, and lack of enforcement. The basic principles of the 
Privacy Act have failed to limit significantly the government's use of 
personal information. In fact, agencies have escalated the collection 
and dissemination of personal information. 41 

For instance, Congress' original intent in enacting the Privacy 
Act /vasthwartedby the government's interpretation of the "routine 
use ' exemption, which allows agencies to disclose personal infor- 
mation if the disclosure is compatible with the purpose for which it 
was collected. 42 Government officials have interpreted the exemp- 
tion to allow the computerized matching of separate agency record 
systems, arguing that detecting waste, fraud, and abuse in govern- 
ment programs is a legitimate government interest, and is thus 
compatible with any original purpose for which records were col- 
lected. 4 ' 

The legislati ve history of the Act, though, makes it clear that the 
routine use exemption was intended to facilitate the exchange of 
information for "housekeeping measures," such as completing payroll 
checks. The purpose of the exemption was to "discourage the 

ERIC 



unnecessary exchange of information to another person or to agen- 
cies who may not be as sensitive tc the collecting agency's reasons 
for using and interpreting the material." 44 A witness at a recent con- 
gressional hearing on computer matching testified that the "routine 
use provision is so big an exemption that you could drive a truck 
through it." 45 

The government's sweeping interpretation of the exemption 
contradicts the Act's core provision — that, as a general matter, 
information collect ed for one purpose may not be used for a different 
purpose without the individual's consent. 

Debate over the Act's routine use exemption began in 1977 
whentheCarter Administration instituted "Project Match," a scheme 
to use computers to compare the Department of Health, Education, 
and Welfare's (HEW) list of welfare recipients with the Civil Service 
Commission and the Defense Department federal payroll files in 
eighteen states. This proposed matching of computerized lists 
sparked a heated feud between those who viewed matching as an 
important investigative and auditing tool, and those who believed 
that the matching of records violated the Privacy Act and intruded 
on individual liberties. 

Mary agency officials cited the Act's routine use exemption to 
justify extensive, inter-agency matching. However, a literal reading 
of the exemption does not appear to permit matching. In a 1 977 letter 
to HEW, the Civil Service Commission's General Counsel opposed 
"Project Match" on the grounds that the matching of disparate 
records violated the Privacy Act. He argued: "Although the literal 
terms of [the exemption] obviously can not be followed with preci- 
sion in practical application to agency operations, it is evident that 
this information on employees was not collected with a view toward 
detecting welfare abuses." 46 The Commission's cornspl went fur- 
ther: 

At the matching stage there is no indication whatsoever 
that a violation or potential violation of law has occurred... 
It cannot fairly be said . . . that disclosure of information 



9 

ERJC 



15 

22 



about a particular individual at this preliminary stage is 
justified by any degree of probability that a violation or 
potential violation of law has occurred. 47 

The corrputer matching proponents prevailed. "Project Match" 
went forward a ,d touched off widespread computer matching 
within the federal government. 48 The outcome of this debate marked 
the political swing away from privacy and towards bureaucratic ef- 
ficiency and revealed the Privacy Act's structural and conceptual 
weaknesses. 

The Privacy Act a'.so prohibits a local, state, or federal agency 
from requiring an individual's Social Security number asacondition 
of receiving services or benefits, unless this is authorized by law. 49 
The drafters were concerned that the Social Security number was on 
its way to becoming a national identifier, and would be used as the 
uniform identifier in linking separate records systems. Yet, Con- 
gress has since not only authorized the use of the number, but 
mandated it. The most striking example is the 1986 Tax Reform Act 
provision requiring all children over the age of five claimed as 
dependents on tax returns to have a Social Security number.™ 

To make matters worse, it is extremely difficult for individuals 
harmed by violations of the Act to bring suit under the Act. The Act's 
lack of both a broad injunctive relief and liquidated damages provi- 
sion prevent meaningful litigation of the Act's intent and applica- 
tion. Privacy violations often result in intangible harm to individu- 
als, making it very difficult to prove actual danv.ges as required bv 
the Act." M 1 J 

In 197?,at the height of the initial controversy over the legality 
of computer notching, the Privacy Protection Study Commission, 
charged with studying the issues raised by the Privacy Act and 
recommending future legislation, issued its report: Personal Privacy 
in an Information A$e." 2 The Commission was created by the Privacy 
Act in a provision adopted during final negotiations and accepted as 
less controversial than creating an Executive branch oversight 
agency. 




?3 



16 



The Commission's report recommended that the Privacy Act be 
more vigorously enforced, and suggested a number ways to make 
the Act more effective. The Ac*, the Commission found, "has not 
resulted in the general benefits to the public that either its legislative 
history or the prevailing opinion as to its accomplishments would 
lead one to expect." 53 The report included a proposed revision of the 
Act that clarified ambiguities, provided individuals with broader 
remedies, and tightened the "routine use" exemption. The Commis- 
sion found that the exemption had "unintended effects," and had 
been "applied loosely and exclusively from the agency's point of 
view." 54 It is important to note that these recommendations were 
published prior to the entrenched institutionalization of computer 
matching. The Commission also recommended that Congress pass 
additional information privacy legislation to protect information 
held in private sector databases. 

Some privacy advocates blame the Act's failure on Congress' 
failure to create a federal privacy oversight agency to implement the 
law. The drafters of the Act did delegate oversight and guidance 
responsibilities to the Office of Management and Budget (OMB). 
However, the Privacy Commission, in its report, found that "neither 
OMB nor any of the other agencies. . . ha ve played an aggressive role 
in making sure that the agencies are equipped to comply with the 

Act and are, in fact, doing so [M]uch of the early momentum 

appears to have been lost." 55 By 1983, the general consensus among 
privacy advocates was that OMB had "virtually abdicated respon- 
sibility" 56 for enforcing and overseeing the Act. 

The Privacy Act is now viewed as a law that requires agencies 
merely lo notify individuals before using personal records for a 
purpose different from that for which they werp collected. Notice 
has become synonymous with consent. Under the Act, individual 
control over personal information is illusory. As Representative 
Glenn English (D-OK) remarked during 1983 Privacy Act overs ; ght 
hearings: 

One of my chief concerns is that the bureaucracy, with the 
approval of OMB, has drained much of the substance out of 



ERLC 



17 

?4 



the Act. As a result, the Privacy Act tends to be viewed as 
strictly a procedural statute. For example, agencies feel free 
to disclose personal information to anyone as long as the 
proper notices have been published in the Federal Register. 
No one seems to consider any more whether the Privacy / ct 
prohibits a particular use of information. 57 

The Act's core principles gave way under pressure from the 
"rise of the computer state/' 58 which provided the government with 
a hard-to-resist temptation to shift its emphasis away frori giving 
individuals some control over personal information to fostering a 
system of nearly unrestrained collection and use. The political 
pendulum swung away from protecting privacy and fostering gov- 
ernment accountability and towards improving bureaucratic effi- 
ciency. Today, the official presumption appears to br the more the 
government knows about you, the better. 

A recent development in government efficiency is the use of a 
technique called "front-end verification." This technique allows 
government officials to verify information electronically by match- 
ing records on a case-by-case basis at the time an individual applies 
for benefits; i.e., at the "front end." For bureaucrats, the appeal of 
front-end verification is that it reduces benefit payment errors; non- 
eligibility is detected before, rather than after, an individual has 
received any benefits. Some argue that this process is less of a 
privacy intrusion than traditional matching because it involves a 
srarch through a particular person's files rather than a massive 
seprch or "fishing expedition." However, the unchecked growth of 
veiification systems linking various databases of personal informa- 
tion on every citizen poses a serious danger to individual d utonomy 
and privacy. 

The success of front-end verification depends on systems that 
provide rapid access to complete and accurate information. The 
threat is thus the same as in computer matching — concern for 
efficiency presses for the aggregation and linkage of multiple agency 
data bases to create a de facto national data base on all citizens. In fact, 
an FBI Advisory Policy Board recently proposed providing the 

9 r 

ERLC 



bureau access to the record systems of the Department of Health 
and Human Services- the Internal Revenue Service, the Social Secu- 
rity Administration, and the Immigration and Naturalization Serv- 
ice. For now, the Bureau's attempt to create a federal agency clear- 
inghouse of information for use by the law enforcement community 
has been defeated. 59 

Despite the long-standing concerns of Congre^ and privacy 
advocates about the government's attempt to establish a national 
data center, it appears that a de facto national data base already exists, 
sustained by on-line linkages that allow information to be stored in 
decentralized form, but instantly assembled at the press of a button. 
A crucial element in this data base linkage is the use of one form of 
identification, most often the Social Security number. 

Congress has encouraged this development by enacting legis- 
lation that undermines the Privacy Act's original principles, allow- 
ing greater information collection and exchange through the man- 
dated linkage and comparison of personal information held in 
separate data bases, and requiring the use of the Social Security 
number to facilitate this process. For instance, in establishing the 
Income Eligibility Verification System (IEVS) in the Deficit Reduc- 
tion Act of 1984, Congress authorized the use of the Social Security 
number for all needs-based programs to make possible the accurate 
identification of applicants and to permit the computerized retrieval 
of information on applicants in discrete data bases containing infor- 
mation on wage, pension, unemployment insurance, and other 
income data, including unearned income from Internal Revenue 
Service (IRS) files. 60 

In addition, the Tax Reform Act of 1986 includes a provision 
requiring all children over the age of five who are claimed as 
dependents on a tax return to have a Social Security number. 61 The 
stated reason for this sweeping requirement is to catch non-custo- 
dial parents who clain their children as dependents. Although tax 
fraud is a legitimate government problem, this provision reflects 
Congress' current unwillingness to address the threat posed by a 
national identification system that numbers all individuals for 
government record-keeping purposes. 62 



19 



Front-end verification— and the systems needed to sustain it- 
pose the grave problem of greater collection of and access to per- 
sonal information, resulting in the ultimate loss of individual con- 
trol, autonomy, and dignity. It is not only the danger of being "just 
a number" that is of concern here, but also providing the govern- 
ment and private institutions the ability to track and profile us from 
birth to death, creating what Arthur Miller termed a "womb-to- 
tomb dossier." 63 

Despite its apparent abandonment of privacy as a primary goal 
of federal policy, in 1988 Congiess enacted the first significant 
amendment to the Privacy Act. The Computer Matching and Pri- 
vacy Protection Act of 1988 64 brings the computerized matching of 
records under the wing of the Act. Under the new law, matching is 
no longer treated as a "routine use" of personal records held by 
federal agencies The Act prohibits agencies from taking any adverse 
action against an individual based on a match until the results have 
been independently verified. Before conducting a match, agencies 
must now enter into written agreements specifying the purpose of 
the match, the records to be matched, and a cost/benefit analysis of 
the match The legislation does not limit in any way the content or 
types of records that can be matched, but does create an important 
procedural framework of more adequate notice to individuals, the 
right to a hearing before benefits are cut off or denied, and manda- 
tory reporting requirements for agencies that match records. 



B. Protecting Personal Records Held By Private Institutions 

In the last eighteen years, Congress has made substantial prog- 
ress in legislation regulating government and private access to 
privately held personal information. 

— In 1970, Congress passed the Fair Credit Reporting Act, 65 
prohibiting credit and investigation reporting agencies that collect, 
store, and sell information on consumers' credit worthiness rrom 
disclosing records to anyone other than authorized customers. The 



ERIC 



20 

P7 



Act requires the agencies to allow consumers .0 review their own 
records and correct inaccurate information. The legislation created 
a legal framework in which the reporting companies could operate, 
and was passed in response to the public's growing awareness and 
concern about personal information maintained by credit reporting 
bureaus. 

— Four years later, the Family Educational Rights and Privacy 
Act 66 was passed, limiting disclosure of educational records to third 
parties. The law requires schools and colleges to let students see 
their records and challenge and correct inaccurate information in 
their records. 

— In 1978, Congress passed the Right to Financial Privacy Act, 67 
in response to the Supreme Court's decision on the privacy of bank 
records in the Miller case and in direct response to the Privacy 
Protection Study Commission's recommendation that Miller be 
superceded by remedial legislation. Congress strengthened the 
Privacy Act's "consent" principle by creating a statutory Fourth 
Amendment protection for bank records. The Right to Financial 
Privacy Act includes a minimum due process standard, and a court 
order provision that requires law enforcement to meet a standard of 
relevance before records can be released. The Act is the result of a 
haid-won compromise between the civil liberties community, bank- 
ers, the Department cf Justice, and Congress. 

— In 1980, Congress passed the Privacy Protection Act 68 to 
prohibit the government from searching press offices without a 
warrant if no one in the office is suspected of committing a crime. 

— In 1 982, Congress passed the Debi Collection Act 69 requiring 
federal agencies to provide individuals with due \ rocess protections 
before an individual's federal dibt information may be referred to a 
private credit bureau. 




—In 1984, Congress enacted the Cable Communications Policy 
Act to safeguard the confidentiality of interactive cable television 
subscriber records. The Act includes the highest court order stan- 
dard ever enacted that must be met by law enforcement lefore 
subscriber records can be disclosed. The Act requires that cable 
subscription records may only be disclosed pursuant to a court order 
that shows by "clear and convincing evidence that the subject of the 
information is reasonably suspected of engaging in criminal activity 
and that the information sought tvould be material evidence in the 
case." Further, the individual must have the opportunity to chal- 
lenge the court order before the records are disclosed. 70 

— In 1983, the Electronic Communications Privacy Act (ECPA) 
was passed, amending the Wiretap Law to cover the interception of 
non-aural communications. Under the Act, law enforcement offi- 
cials may not obtain information held by a data communications 
company, such as MCI, without a warrant that meets the probable 
cause standard. ECPA also overturns the Supreme Court's ruling in 
Smith v. Maryland that telephone toll records are not private. Under 
ECPA, law enforcement officials must show there is "reason to 
believe the contents of a wire or electronic communication, or the 
records or other information sought, are relevant to a legitimate law 
enforcement inquiry," before obtaining access to transactional data 
such as telephone toll records. ECPA represents a recognition of the 
need to protect information regardless of the technological advance^ 
that have shaped its use. 

— The Video Privacy Protection Act of 1988, passed at the end 
of the 100th Congress, includes a strong court order standard 
modeled on the Cable Act. Videocassette rental records, like cable 
subscriber records, can reveal information about individual prefer- 
ences and political beliefs. Congress has been quick to create strong 
protections in such areas where First and Fourth Amendment con- 
cerns intersect. 71 

These recent laws reflect Congress 7 willingness to fashion strict 
disclosure stanu w ids for sensiti/e information held by private insti- 
tutions. Implicit in these new law* is a legislative recogrUion that 



22 



expectations of privacy can be created and enforced- a particularly 
crucial recognition in an age in which information practices continue 
^oTour constitutionally protected "reasonable" expectations. 

IV. PROPOSALS FOR THE FUTURE 
A. The Rewrite of the Privacy Act 

There is a genera', consensus that the Privacy Act of 1974 is 
ineffective, obsolete, and needs to be rewritten.- Neither the ab- 
sence of a vigorous privacy protection commission nor scattered, 
weak implementation by OMB can be bu rned exclusively for the 
law's failure. At this stage, the emphasis si ould be on rewriting to 
Privacy Act. A privacy oversight agency without s rong clear 
provisions to enforce, would continue to be a political tool in the 
hands of changing administrations. 73 

Only enforceable limits on what personal information can be 
collected and how it can be used can give individuals meaningful 
control over the information they divulge in exchange for receiving 
benefits and services from the government. The Act currently lacks 
such substantive limits. 

In addition, much of the Act has been rendered obsolete by 
advances in information technology and the drive to adopt new 
technological capacities for data collection and consolidation. Re- 
cent statutes take into account more modem techniques of intrusion, 
but, on the whole, privacy legislation has not effectively erected 
barriers around information. Instead, the Privacy Act and the bulk 
ofinformationprivacystatutesaimedatinformationheldby private 

institutions, require only that a series of procedura maneuvers be 
completed before an agency or institution can divulge records. 

Due process safeguards are more than just good "data use 
manners," and may be genuinely protective in some instances, but 
more is needed rotect individuals. Notice and consent proce- 
dures are not % enough protection for personal »fora»tion in 
the control of . ft .vemment; the government's collection and use of 



9 

FRIC 



23 

30 



»f2LX Vu T tt0n y S "? " f0r tax ' census ' and P« blic benefit 
purposes, should be limited, and even, in some cases, prohibited. Such 
limits are necessary to give individuals meaningful control over 
mformahon about themselves; to grant people the right to control 
what the government (and others) may know about their lives. 

The law should be redrafted to strengthen the Act's fundamen- 
hPvHuJ S/ . g,Ving individuak control over information 

and * n g ° Vemment aeencies eith *r by law (i.e. for census 
and tax purposes) or as a condition of receiving government benefits 
or services. Government agencies should be authorized to collect 
only information that is necessary and relevant to their particular 
purpose. Agencies must inform individuals of the reasons why 
personal information is being collected and for what purposes it will 
be used. An individual must have the right to challenge a particular 
collection or use either through administrative or court action. The 

M\Z\,f T 1 ? indudeS 3n 3dequate P rocedure for a S e ™*> to 
SvesTigatlon 6 * ^ PU ™ t0 8 laW ^rcement 

In Edition the Act's "routine use" exemption must be re- 
vamped so that the law will work as intended . A clear and restrictive 
definition of routine use must be added to the statute clarifying that 
disclosure for a routine use must be consistent with the orfeinal 
purpose for which the information was initially collected. Individu- 
als must have the right to challenge a proposed routine use on the 
grounds that it is not consistent with the purpose for which the 
information was originally collected. Routine use disclosures under 
this definition must be benign and not for the purpose of taking 
adverse action against an individual. 

Th e Privacy Act needs a new remedy section that provides both 
liquidated damages and injunctive relief for any aggrieved individ- 
ual. Currently, an indiviual may not sue under the Act unless he or 
«■ Ca " P™^™ 11 ™ 1 ^d intentional misconduct by an agency 

h ™ ^ U3lS T St be ?ble 10 C0llect damaees ^ intangible 
harms caused by violations of the Act. 



24 



B. Information Privacy Policy Initiates 



ERIC 



For the future, privacy advocates must push for policy initia- 
tives to protect medical, insurance, personnel, and retail records as 
well as personal information held by the government. The policy 
goal is the creation of federal statutory rights of information privacy, 
tailoring standards that incorporate a balance between the sensitiv- 
ity of the information at stake and the institutional justification or 
need for the information— the more sensitive the information, the 
more compelling the need must be for its collection and the higher 
the standard must be for its disclcuie to others. 

The guiding principles in drafting legislation should be: 

1) Information collected for one purpose should not be 
used for a different purpose without the individual's con- 
sent. Any unauthorized use of the information must give 
rise to an enforcement action by the harmed individual. The 
goal is to create legislatively mandated expectations of pri- 
vacy in information. 

2) Policy should be developed with an eye towards new 
advances in information technology and telecommunica- 
tions. It may not be possible to anticipate every advance, but 
the law should be elastic enough to apply to information 
regardless of whether it is in electronic or manual form. In 
this way, the numbing cliche that technology is constantly 
outpacing the law may be overcome. 

3) Legal limits should be placed on the collection and use 
of sensitive information— the more sensitive the infor- 
mation, the more rigorous the disclosure standard. Per- 
sonal information, such as census data and certain medical 
records, should never be disclosed for any purpose, whereas 
less sensitive records might be available for legal proceed- 
ings. For sensitive information, law enforcement officials 
must demonstrate probable cause or reasonable suspicion 



25 

32 



to believe a crime has been committed and that the informa- 
tion they seek relates to that crime. Individuals must receive 
notice before a court-ordered disclosure, and have an op- 
portunity to challenge the disclosure. 

4) Individuals must be provided w» a easy access to then- 
records, including access to computerized records, for the 
purpose of copying, correcting, or completing informa- 
tion in the records. Computer technology should allow in- 
diviuals on-line access to their records. 74 Legislation should 
mandate an access procedure, and require that information 
be kept accurate, complete, and up-to-date. Records that 
are no longer relevant for the purpose for which they were 
collected should be destroyed. 

5) Exemptions for non-disclosure should be clearly justi- 
fied and narrowly tailored to suit the requestor's need. Ex- 
emptions should explicitly define the intended scope of the 
allowable disclosure to avoid expansion or misinterpreta- 
tion of the provision. 

6) Legislation should include enforcement mechanisms, 
such as injunctive relief, civil damages, criminal penal- 
ties, and reimbursement of attornejr's fees and costs. By 
putting teeth into information privacy legislation, indi- 
viduals will be able to enforce the law and seek redress for 
violation of their privacy rights. Injunctive relief can pre- 
vent damage before it occurs, damages can compensate 
aggrieved individuals, and criminal penalties can punish 
those who violate the law. In addition, these individual 
enforcement mechanisms can be buttressed by institutional 
enforcement and oversight, such as by the promulgation of 
implementation guidelines, giving Privacy Act officers in 
each agency greater enforcement powers, and strengthen- 
ing congressional oversight. Each of these enforcement 
mechanisms will deter unauthorized information gather- 
ing and exchange. 



ERIC 



26 



Momentum exists for building on recent successes to press for 
new information privacy initiatives. Work should continue towards 
the passage of laws that incorporate standards tailored to the sensi- 
tivity of the information involved. 

V. CONCLUSION 

Our right to privacy dwindles each year, giving way under the 
tremendous institutional pressure to collect and use information. 
The push for strong laws to protect information privacy is not a 
partisan issue. As stated in the 1980 Republican Party Platform: 

Government in recent years, particularly at the Federal 
level, has overwhelmed citizens with demands for personal 
information and has accumulated vast amounts of such 
data through the IRS, the Social Security Administration, 
the Bureau of the Census, and other agencies. Under certain 
limited circumstances, such information can serve legiti- 
mate societal interests, but there must be protection against 
abuse. . . We are alarmed by Washington's growing collec- 
tion and dissemination of such data. There must be protec- 
tion against its misuse and disclosure. 

The momentum to protect personal information held by fed- 
eral agencies, sparked by years of hearings, privacy abuses and 
culminating in the Watergate scandal, was maintained long enough 
for Congress to pass the Privacy Act of 1974. In addition, Congress 
has responded to the pressing need to protect personal information 
maintained by private institutions. Privacy advocates must con- 
tinue to seize upon such targets of opportunity to heighten public 
awareness about the need for privacy legislation. Advances in 
information technology create legislative opportunities. Again, the 
Department of Health and Human Services is moving forward with 
a plan to link computers in 52,000 pharmacies nationwide to central- 
ize, exchange, and audit " ^formation on Medicare beneficiaries. The 
FBI is proposing a massive expansion of its central computer system. 
These proposals all pose serious threats to individual privacy. 
Privacy advocates must inject their voices into the planning process 
to create a forum for debate on information and individual privacy. 

27 

ERiC 14 



Notes 



1 . Olmstead v. United States, 277 U.S. 438, 478 (1928) (J. Brandeis dissenting). 

2. House Comm. on Government Operations, Who Cares About Privacy? 
Oversight of the Privacy Act of 1974 by the Office of Management and Budget and 
the Congress, U.K. Rep. 455, 98th Cong., 1st Sess. (1983). 

3. L. Harris, The Road After 1984: A Nationwide Svrvey of the Public and Its 
Leaders on the New Technology and Its Consequences for American Life (1983) 
(hereinafter Harris Survey). This Harris Survey documented that in 1983 
forty-eight percent of the public described themselves as "very concerned" 
about technology and threats to personal privacy, double those in 1978. 
Sixty percent of the public believe the use of computers must be severely 
limited to safeguard privacy. A majority of the public takes the position that 
the release of personal information by government agencies to other agen- 
cies seriously invades personal privacy. 

4. Harris Survey. 

5. In 1987, Congressman Don Edwards (D-CA) convened a panel of privacy, 
criminal justice, and computer security experts to evaluate a set of FBI- 
developed changes to its information systems. The pane's report, submit- 
ted for consideration to the FBI's Advisory Policy Board (APB), appears to 
have had an impact on the decisionmaking process. Of the 246 proposals 
onginallycontemplat"dbytheAPB,only81 were ultimately recommended 
tor implementation. The panel is continuing to critique an FBI proposal to 
us^ the NCIC to trock and surveil individuals suspected of certain crimes. 

6. The proposed system involves the participation of 52,000 pharmacies 
across the nation in a computer network designed to process electronically 
the prescription drug bills of 32 million Medicare beneficiaries. The Health 
Care Financing AdministrationbranchofHHSiscurrentlyseekinginputon 

the implementation of the system, with a proposal for funding to be 
submitted in the fall of 1989. Privacy advocates plan to press for the 
incorporation of substantive privacy protections before the funding pro- 
posal is submitted. 



9 

ERLC 



7. Office of Technology Assessment, Federal Government Information 
Technology: Electronic Record Systems and Individual Privacy, at 1 (1986) 
(hereinafter OTA Report). 

8. Bloustein, Privacy as an Aspect of Human Dignity: An Answer to Prosser, 
39N.Y.U. L. Rev. 962 (1964). 

9. Forpurposes of this paper, theability to control information about one's 
self is termed "information privacy/' traditionally defined as "the claim of 
individuals, groups or institutions to determine for themselves when, how, 
and to what extent information about them is communicated io others." 
A. Westin, Privacy ana Freedom, at 39 (1967). 

10. NAACP v. Alabama, 357 U.S. 449 (1958); Stanley v. Georgia, *94 U.S. 557 
(1969). 

11. Mapp v. Ohio, 367 U.S. 643 (1961). 

12. Griswold v. Connecticut, 381 U.S. 479 (1965). 

13. Meyer v. Nebraska, 262 U.S. 390 (1923). 

14. Boyd v. United States, 116 U.S. 616 (1886); Katz United States, 389 U.S. 
3^7 (1967). 

15. Shattuck, In the Shadow of 1984. National Identification Systems, Computer 
Matching, ana Privacy in the United States, 35 Hastings L.J. 991 (1934). 

16. Boyd v. United States, 116 U.S. 616, 630 (1886). 

17. Shortly after Boyd, came the publication of Warren and Biandeis, The 
Right to Privacy, 4 Harv. L. Rev. 193 (1890). 

18. NAACP v. Alabama, 357 U.S. 449 (1958). 

19. Katz v. United Statu*, 389 U.S. 347, 353 (1967). 

20. In 1986 the Supreme Court, in Bodoers v. Hardwick, 478 U.S. 186 (1986), 
rehearing denied, 478 U.S. 1039 (1986), upheld Georgia's sodomy statute, 
finding that one does not have a constitution, 1 right to privately engage in 
consensual sexual conduct. In that case, Georgia charged a man with 
violating the state's criminal sodomy statute after "catching" fcm in the act 
in his own bedroom. The police entered the home to execute a warrant for 
a traffic violation. 

Q 30 

ERIC 36 



21. 56U.S.L.W 4409(U.S.May 16, 1988) (No. 86-684). 



22. U viller, "The Fourth Amendment: Does it Protect Your Garbage?", The 
Nation, October 10, 1988, at 303. 

23. 425 U.S. 345 (1976). 

24. A similar analysis was used to find that one does not have a reasonable 
expectation of privacy in telephone toll records, Smith v. Maryland, 442 U.S. 
735(1979). 

25. Banks, in essence, perform a fiduciary/trustee function with regard to 
customer records. Thus, a customer may relinquish physical posspssion of 
his or her records, while still maintaining some element of co. ♦'•ol or 
ownership of the records. 

2d. United States v. Miller at 449^52, quoting Burrows v. Superbr Court, 529 
P. 2d 590 (1974) 

27. 429 U.S. 589 (1977). 

28. Id. at 605. In a recent case involving whether the FOI A applies to the 
release of criminal history records maintained by the FBI, Judge Starr of the 
District Court of Appeals noted in his dissent that if the FBI is required to 
release records from its name-indexed, computerized files, "the federal 
government is thereby transformed inone fell swoop into the clearinghouse 
for highly personal information, releasing records on any person, to any 
requester, for any purpose. . . . [T]his new-fangled regime will have a 
pernicious effect on personal privacy interests in conflict with Congress' 
express will." The Supreme Court agreed to hear the case, and briefs were 
submitted in Juno, 1988. Reporter's Committee for Freedom of the Press v. 
Department of justice, 831 F.2d 1 1 24 (D.C. Cir. 1 987), cert, granted, 56 U.S.L. W. 
T?i8 (U.S. April 18, 1988) (No. 87-1379) 

29. See text at 21-22 infra. 

30. The Computer and Invasion of Privacy: Hearings Before the Special Subcomm 
on Invasion of Privacy of the House Comm. on Government Operations, 89th 
Cong., 2d Sess. (1966) (hereinafter 1966 House Privacy Hearirgs); Federal 
Data Banks, Computers and the Bill of Rights: Hearings Before the Subcomm, on 
Constitutional Rights of the Senate Comm. on the Judiciary, 92nd Cong., 1st Sess. 
(1971 ) (hereinafter 1 971 Senate Privacy Hearings;and Privacy: TheCollection, 



ERLC 



31 

37 



Use and Computerization of Personal Data: Joint Hearings Before the Subcomm. 

onPrivacyandlnforimtionSystemsoftheSemteCmm.onGovem 

and the Subcomm. on Constitutional Rights of the Senate Comm. on the Judiciary, 

93rd Cong., 2d Sess. (1974). 

31. 1966 House Privacy Hearings, at 2 (statement of Rep. Cornelius 
Gallagher (D-NJ)). 

32. Id. at 6 (statement of Rep. Horton). 

33. The House Special Committee on Invasion of Privacy released a report 
in 1 968 "Privacy and the National Data Concept/' recommending that plans 
for a data center be postponed until the confidentiality and security of 
centralized information could be assured. 

34 1966HousePrivacyHearings / atl20-122(testimonyofPaulBaran / Rand 
Corp.) 

35. H.R. Rep. No. 1416, 93rd Cong., 2d So>s. 3 (1974), reprinted in, Source 
Book, at 296. Also during this period, a number of books were published 
that signaled the decline of freedom in the new age of computerized data 
banks. See Miller, The Assault on Privacy (1971) and Westin and Baker, 
Databanks in a Free Society. Computers, Recordkeeping, and Privacy (1972). 

36. U.S. Department of Health, Education, and Welfare, Records, Computers 
and the Rights of Citizens. Report of the Secretary's Advisory Committee on 
Automated Personal Data Systems (1973). 

37. Privacy Act of 1974, 5 l.S.C §552a (2)(a) (1974). 

38. Cong. Rec.S. 6741 (May l,1974)(IntroductoryRemarkscfSen.Ervinon 
S 341 8) reprinted in Senate Comm. on Government Operationsand bubeomm. 
on Government Information and Individual Rights of the House Comm. on 
Government Operations, 94th Cong., 2d Sess., Legislative History of the 
Privacy Act of 1974 S, 3425 (Public Law 93-579): Source Book on Privacy, 5 (Joint 
Comm. Print 1976) (hereinafter Source Book). 

39. Id a[30, reprinted in, Source Bock, at 183. The Senate Committee report 
on the Privacy Act described the burgeoning use of the Social Security 
number as ''one of the most serious manifestations of privacy concerns in 
the nation," clearing the way for a national data bank. Id. at 28, jeprinted in, 
Source Book, at 181. 



ERLC 



32 

38 



40. S.Rep.No.ll83 / 93rdCor,g. / 2dScss.l(1974) / r e pn»fedm,SourceBook / 
at 154. 

41. In a 1986 report, the congressional Office of ^^i 0 ^.^ 55 ^^ 
(OTA) found that federal agencies and departments held 35 billion records 
in the record systems as defined by the Privacy Act. Nearly half of those 
systems were computerized, with agencies sporting an >ncrcase m 
microcomputers from a few thousand in 1980 to 100,000 .n 1985. OTA 
Report, at 12. 

42. 5 U.S.C.§ 552a (b)(3) (1974). 

43 A 1980 notice of a proposed match published in the Federal Register 
stated that a match between the records of Office of Personnel Manjement 
(OPM) and the Veterans' Administration was for a routine use . An 
integral part of the reason these records are maintained is to protect the 
legiLate interests of the government, and therefore, such a disclosure ,s 
compatible with the purposes for maintaining these records. 



44. Source Book, at 859-860. 



45. ComputerMatcMngandPrivacyProtectionActo^ 

Before the Subcomm. on Oversight of Government Management of the SenaU 
Comm.onGo W r„m e nf fl /^irs,99thCong.,7dSess.at29(Comm.Printl986) 

(Ronald Plesser testifying on behalf of the American Bar Association). 

46. Letter from Carl F. Goodman, General Counsel, Civil Service 
Commission, to Charles Ruff, Deputy Inspector General Dcpartrncn 
Health, Education and Welfare, (July 27, 1977). repnnted in, Oversight of 
Computer Matching to Detect Fraud and Mismanagement " Government 
Prog\ams:HearMpBeforetheSubcomm.onOversightofte^ 

of the Senate Comm. on Government Affairs, 97th Cong., 2d Sess. at 122-25 
(Comm. Print 1982). 

47. Id. 

48 A 1986 Office of Technology Assessment (OTA) report found that 
matching has become an integral part of the operation of many government 
agencies In 1984, agencies conducted 110 separate matching P™&*™> 
totalling nearly 700 matches and involving 2 billion separate records. OTA 
Report. 




49. 5 U.S.C § 552a (1974). 

33 



39 



50. Tax Refonr Vet of 1986, 26 U.S.C. § 6109 (e) U986). 

51. In contrast, ali of the federal wiretap statutes provide for liquidated 
Us2 8 § 2703 < e i986) he El0Ctr ° niC Communicarions Privac y Act of 1986, 18 

52. The Privacy Protection Study Commission, The Privacy Act of 1974- A P 
Assessment, (1977) (hereinafter Pnvacy Protection Commission Report) 

53. Privacy Protection Commission Report, app. 4, at 113. 

54. /d.at 120. 

55. M.at 21. 

56. OversightofthePriwcyActofl^HearingsbeforeaSubcomm.oftheHouse 

nnZtsZTTTr?^ ^ ° 8lh C ° ng ' 151 ^ 259 (1983) ^™*x 
of John Shattuck, ACLU) (herr aafter 1983 House Privacy Act Oversight 

Hearings). See <uso, House Comm. on Government Operations, Who Cares 

About Pnvacy? Oversight of the Privacy Act of 1974 by the Office of Management 

and Budget and the Congress, H.R. Rep. No. 455, 98th Cong., 1 st Sess. (1 983). 

Rcp'eS 

58. David Burnham, The R*e cf the Computer State (1985). 

59. See note 4 supra. 

60. Deficit Reduction Act of 1984, 98-369, 98 Stat. 494 (1984). 
61.26U.S.C.§6109(cVi986). 

62. The leg.slati ve history of the Privacy Act reveals Confess' previously 
deep concern about the expanded use of the Social Security number 
lOJnce the Social Security number is set as a universal identifier each 
person would leave a trail of personal data behind him for all his life which 
could be immediately reassembled to confront him. . [WJe can be 
pinpointed wherever weaie, we can be more easily manipulated, wecanbe 
more easily conditioned and we can be more easily coerced." Cone Rec 
t^L- ? ! 2 } (SlalCmCnl ° f Goldwater), reprinted in, Source 
Book, at 760 In addition, government agencies are considering proposals 
for a national identification card to enforce- the Immigration Reform Act to 
distribute food stamps, and to process welfare applications 



ERIC 



34 

40 



63. 1971 Senate Privacy Hearings, pt. 1, at 9. 

o4. The Computer Matching and Privacy Protection Act of 1988, 5 U.S.C 
552a (1988). 

65. §15 U.S.C. §1681 (1970). 
66.20U.S.C.§1232g (1974). 
67.12U.S.C§3401 (1978). 
68. 42 U.S.C. § 2000aa (1980). 
69.31 U.S.C. §952 (1982). 

70. Cable Communications Policy Act, 47 U.S.C. § 551 (1984). 

71. The initiative for the Video Privacy Protection Act grew out of the 
unauthorized disclosure cf the Bork family's video rental list to a reporter 
during Judge Robert Bork's confirmation hearings for the United States 
Supreme Court. At that time, many Senators expressed outrage at this 
intrusion into the Bork family's privacy, characterizing the disclosure as an 
"issue that goes to the deepest yearning of all Americans that we ...cherish 
our freedom...(and] we want to be left alone." Nomination of Robert H. Bork 
to be Associate Justice of the Supreme Court of the United States: Hearings before 
the Senate Committee on the Judiciary, 100th Cong., 1st Sess., 1374 (1987) 
(remarks of Sen. Patrick Leahy, D-VT). 

72. In its 1986 report, OTA concluded that "federal use of new electronic 
technologies in processing personal information has eroded the protec- 
tions" of the Privacy Act. OTA found that many information practices are 
not covered by the Act, r*nd that there is scant oversight and inadequate 
remedies to ensure agency compliance. OTA Report at 4. 

73. In 1977, the Privacy Protection Study Commission recommended that 
a privacy protection agency be established, but in conjunction with the 
passage of strong, enforceable information privacy laws. At that point, the 
Privacy Act should have been strengthened by legislative amendment, 
agency regulations, and strict congressional oversight. 

74. Computer technology should be used to enhance priv ry. For instance, 
computer audit trails can be used to inform citizens about how information 
about them is used, and may act as a deterrent to unauthorized access and 
unnecessary uses of personal information. 

O . 35 



About This Series 

ThfepublicaHonisoneofeigto^ 

^contacting the foundation at the address below. 
Papers in this series include: 

1 ne Role of Public Policy in the I** Television Marketplace 

gnive "irofleeds and University of Maryland 

2 ^a^MSooshan 111 and Louise Amheim 

Shoo'shan & Jackson Inc. 

3 Cliarzmg for Spectrum Use 

Henrv Geller and Donna Lamport 
wSngtcr enter for Public Policy Research 

4 A Fj^rfJS^- Prlva % T "< f ° T **** 

jerrv Berman and Janlori Goldman 
American Civil Liberties Union 

5 Watching the Watchers: The Coordination of 
Federal'Privacy Policy 

George trubow 

The John Marshall Law School 

Ovvortumtie< and Realities at OMB 
Garv Bass and Da\ id Plocher 
OMB Watch 

7 -\ Pu^uiential Initiative on Information Poluy 

John Shatmck and Muriel Monsey Spence 
Harvard University 

8 Vic federal Structure for Telecommunication* Poluy 

Duke University 

Individual copies are $6 50 each, inc.ud.ng postage r and 
handling. The boxed set of eight papers is available or S3100, 
n c udme postage and handling. A bulk discount of 10 * .s 
SaE orders of 10 or more copies of the same paper 
Checks or money orders should be made payable to the 
Benton Foundation and mailed to. 

Policy Options Project 
Benton Foundation 
1776 K Street, N.W 
Washington, D.C 20006 



B BENHON FOUNDATION 

1776 K Street, N.W. 
Washington, D.C. 20006 



43 



